Is port isolation the answer?
Posted: Tue Feb 17, 2015 12:00 am
We are trying to set up a new WISP Switch and consolidate multiple switches (Tough Switches) in the process.
However, because of the way we have things setup through a Netequalizer (a bandwidth shaper that is essentially a transparent bridge with two Ethernet interfaces) we have had to use two separate switches to make everything work. The Netequalizer bridges all of the traffic from our internal network and connects it to our 'Internet' feed, managing our bandwidth in the process.
Basically we have one VLAN (1) that is untagged as well as several other tagged VLANs (100,120,140,160) that flow through two separate switches. We use an Edgerouter Pro for our Internet facing router which has its internal LAN interface (eth0 configured with VLAN 1 untagged; 100, 120,140, and 160 tagged) connected to port 1 on a ToughSwitch, which has the same configuration (VLAN 1 untagged; 100, 120,140, and 160 tagged) while port 2 has the same configuration (VLAN 1 untagged; 100, 120, 140, and 160 tagged) that is connected to the 'External' port on the Netequalizer. The 'Internal' port on the Netequalizer is connected to another ToughSwitch entirely with the same VLAN config I have referenced on every port (VLAN 1 untagged; 100,120,140, and 160 tagged) while port 2 on this ToughSwitch is configured identically (VLAN 1 untagged; 100, 120, 140, and 160 tagged) with an AirFiber plugged into it and then which backhauls the VLANs to another WISPSwitch on a port that has the same VLAN Configuration (VLAN 1 untagged; 100,120,140 and 160 tagged). The WISPSwitch at the other end of the AirFiber link, breaks out the VLANs and connects them to the respective Access Points so that VLAN 120 breaks out untagged on Port 5. The Netequalizer has proven to sometimes be finicky in linking up with the AirFiber and the EdgeRouter directly, which is why we have had the ToughSwitches in between.
I was thinking I could basically just set two ports in their own 'Untagged' VLAN (VLAN 500 for example) that wouldn't be shared with any other ports to eliminate the need for another switch with just two devices plugged in (the LAN port on the EdgeRouter and the 'External' port on the Netequalizer) along with the tagged VLANs, but keep going around and around in seeing a loop being created and the WISPSwitch not knowing the direction packets should flow (through the Netequalizer).
I realize I probably could do a better job in explaining but am hoping Port Isolation would allow this to work. Am I on the right track?
However, because of the way we have things setup through a Netequalizer (a bandwidth shaper that is essentially a transparent bridge with two Ethernet interfaces) we have had to use two separate switches to make everything work. The Netequalizer bridges all of the traffic from our internal network and connects it to our 'Internet' feed, managing our bandwidth in the process.
Basically we have one VLAN (1) that is untagged as well as several other tagged VLANs (100,120,140,160) that flow through two separate switches. We use an Edgerouter Pro for our Internet facing router which has its internal LAN interface (eth0 configured with VLAN 1 untagged; 100, 120,140, and 160 tagged) connected to port 1 on a ToughSwitch, which has the same configuration (VLAN 1 untagged; 100, 120,140, and 160 tagged) while port 2 has the same configuration (VLAN 1 untagged; 100, 120, 140, and 160 tagged) that is connected to the 'External' port on the Netequalizer. The 'Internal' port on the Netequalizer is connected to another ToughSwitch entirely with the same VLAN config I have referenced on every port (VLAN 1 untagged; 100,120,140, and 160 tagged) while port 2 on this ToughSwitch is configured identically (VLAN 1 untagged; 100, 120, 140, and 160 tagged) with an AirFiber plugged into it and then which backhauls the VLANs to another WISPSwitch on a port that has the same VLAN Configuration (VLAN 1 untagged; 100,120,140 and 160 tagged). The WISPSwitch at the other end of the AirFiber link, breaks out the VLANs and connects them to the respective Access Points so that VLAN 120 breaks out untagged on Port 5. The Netequalizer has proven to sometimes be finicky in linking up with the AirFiber and the EdgeRouter directly, which is why we have had the ToughSwitches in between.
I was thinking I could basically just set two ports in their own 'Untagged' VLAN (VLAN 500 for example) that wouldn't be shared with any other ports to eliminate the need for another switch with just two devices plugged in (the LAN port on the EdgeRouter and the 'External' port on the Netequalizer) along with the tagged VLANs, but keep going around and around in seeing a loop being created and the WISPSwitch not knowing the direction packets should flow (through the Netequalizer).
I realize I probably could do a better job in explaining but am hoping Port Isolation would allow this to work. Am I on the right track?